Part I: Setup (the boring bit that makes it work)05
Chapter 05Step 4
Step 4: One key from you, and full access
One key from you. I make the rest.
You make one key. The agent makes the rest.
"Shouldn't I give the agent as little access as possible?"
In a company with 200 engineers, yes. For your own bakery site, no.
Every permission you leave out is a moment later where the agent stops, says "I don't have access to do that", and sends you into a dashboard to find the checkbox it meant. That's the exact thing this guide exists to kill.
So the agent gets broad access to your own accounts, and the keys get protected properly instead: they live in the vault, never in chat, never in code, and they expire on their own.
The Cloudflare bootstrap key
Instead of you building a token with fifteen permission rows (it's miserable, I've done it enough times), you make a small key whose only job is to let the agent create its own full-access token.
- Cloudflare dashboard → profile icon (top right) → Profile → API Tokens → Create Token.
- Find the Create Additional Tokens template → Use template.
- TTL: set an end date one week out. The agent only needs it once. After that it has its own token.
- Continue to summary → Create Token. Copy it.
- Bitwarden → Secrets Manager →
websitesproject → New secret. Name:CLOUDFLARE_BOOTSTRAP_TOKEN. Value: paste. Save.
That's the whole chapter's clicking.
Personal details are blurred. Press play, it's silent and loops.
In chapter 6 the agent uses this to create CLOUDFLARE_API_TOKEN: one token with edit access to Workers, DNS, the database, file storage, email, spam protection and everything else a site needs, across all your domains, valid for a year. It saves it to the vault itself.
GitHub doesn't need a key in the vault
GitHub has its own sign-in flow for command-line tools. In chapter 6 the agent starts it, a browser window opens, you click Authorize. That's it. GitHub keeps that login in your computer's keychain.
Later keys
Two more things need a human, and they come up in their own chapters:
- Google (chapter 11): you sign in once in the browser and accept Google's terms in Analytics and Tag Manager. The agent creates the actual key.
- Stripe (chapter 10): Stripe needs to verify your business, so you create the account and copy one key into the vault.
Checklist
On a phone, swipe left and right to turn pages.